daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit f2b790878056e40e0c034518a748f2b7f2b5f9b6
parent 6e2600541b6cc993eb2ae7fe244363b1f21c4bc5
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Sun, 20 Sep 2026 04:01:19 +0100

recycle-bin: add SID-filtered Restore-ADObject and Get-ADUser verify

Native restore now shows the SID-filter form piping straight to Restore-ADObject, plus a Get-ADUser check that the object returned enabled under its OU. Matches the TombWatcher writeup recording.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

Diffstat:
Msrc/content/sheets/active-directory/ad-recycle-bin-enumeration.md | 7++++++-
1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/src/content/sheets/active-directory/ad-recycle-bin-enumeration.md b/src/content/sheets/active-directory/ad-recycle-bin-enumeration.md @@ -108,8 +108,13 @@ bloodyAD -u "$U" -d "$DOMAIN" -p "$P" --host "$DC" set restore 'S-1-5-21-…-111 ``` ```powershell -# Windows — restore by deleted-object DN (from Get-ADObject -IncludeDeletedObjects) +# Windows — restore natively. Easiest: filter the bin by the SID that owns the +# edge and pipe straight to Restore-ADObject (no need to copy the mangled DN): +Get-ADObject -Filter "objectSid -eq 'S-1-5-21-…-1111'" -IncludeDeletedObjects | Restore-ADObject +# or restore by the deleted-object DN (from Get-ADObject -IncludeDeletedObjects): Restore-ADObject -Identity '<distinguishedName-with-\0ADEL:GUID>' +# confirm it came back, enabled, under its old OU: +Get-ADUser -Identity <restored> | Select-Object SamAccountName,Enabled,DistinguishedName ``` If you control the restored object (e.g. `GenericAll` over its OU covers restored children too), take it over — reset the password or add shadow credentials: